Database/Firmware, BMC & network fabric

Insyde InsydeH2O (NvmExpressDxe, incorrect pointer checks): The NVMe driver's pointer validation is wrong, allowing
Impact
The NVMe driver's pointer validation is wrong, allowing tampering with both SMRAM and OS memory. The driver reaches the NVMe data path - datasets, checkpoints, weights on a GPU node - and the bug hands an OS-level attacker ring -2 on top of it. Distinct from the DMA race in SA-2022055 and separately fixed; a node can carry one and not the other.
Who can reach it
Local admin/root on the host OS invoking the vulnerable software SMI with attacker-chosen pointers. On bare-metal GPU rental this is exactly the privilege the tenant already holds on their leased node.
What to do
Firmware flash from the server OEM, not from Insyde - the fixed Insyde kernel has to be rebased by Dell/HPE/Lenovo/Supermicro and re-qualified before it reaches you, which for this batch ran months behind Insyde's own release. One reboot per node, so schedule it against a GPU drain. Fixed in kernel 5.1 / 05.17.23 through 5.5 / 05.52.23. The compensating control that actually works here is the IOMMU, and Insyde says so in the advisory: enable VT-d/AMD-Vi with pre-boot DMA protection so the ACPI runtime buffer the handler reads is not reachable by an untrusted device. That is a BIOS setting, deployable fleet-wide without a flash, and it should be on already on any node that passes devices through to tenants. Patch the batch, not the CVE - Insyde filed one advisory per driver for the same defect, so fixing this one leaves every sibling handler reachable.
References
Related entries
- Insyde InsydeH2O (SdHostDriver and SdMmcDevice, untrusted pointer use): One advisory covering both SD layers: untrustedCVE-2022-29279 · Insyde InsydeH2O (SdHostDriver and SdMmcDevice, untrusted pointer use)High
- Insyde InsydeH2O (PnpSmm initialization, SMRAM corruption via later PNP SMIs): An initialization-order defect: PnpSmm'sCVE-2022-30771 · Insyde InsydeH2O (PnpSmm initialization, SMRAM corruption via later PNP SMIs)High
- Insyde InsydeH2O (PnpSmm function 0x52, SMBIOS write address manipulation): PnpSmm function 0x52 takes an addressCVE-2022-30772 · Insyde InsydeH2O (PnpSmm function 0x52, SMBIOS write address manipulation)High
- Insyde InsydeH2O (UsbLegacyControlSmm): A classic SMM callout: code running inside SMM calls out to a function pointerCVE-2022-35408 · Insyde InsydeH2O (UsbLegacyControlSmm)High
- Insyde InsydeH2O (MebxConfiguration DXE driver): A UEFI variable that the OS can write is read back by BIOS codeCVE-2022-36337 · Insyde InsydeH2O (MebxConfiguration DXE driver)High
- AMI MegaRAC SPx (Dynamic Redfish Extension): Code injection executed via the Dynamic Redfish Extension interfaceCVE-2023-34330 · AMI MegaRAC SPx (Dynamic Redfish Extension)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.